[Crash] Avoid iOS 16 URL parsing crash in stringWithUserAndPasswordStripped - #916
Open
o-nnerb wants to merge 1 commit into
Open
[Crash] Avoid iOS 16 URL parsing crash in stringWithUserAndPasswordStripped#916o-nnerb wants to merge 1 commit into
o-nnerb wants to merge 1 commit into
Conversation
URL.user()/password() (the percent-encoded accessors) share internal parsing code with URL.host(percentEncoded:) on iOS 16, and calling them there can crash inside host parsing even though host is never touched here. Gate the fast path on iOS 17 instead, so iOS 16 falls back to the legacy user/password properties, which don't hit the bug. See https://forums.swift.org/t/70452 for the same crash signature.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
URL.stringWithUserAndPasswordStripped(added in #906, used by the built-in span attribute support from #857) calls the percent-encodedURL.user()/URL.password()accessors when#available(macOS 13.0, iOS 16.0, tvOS 16.0, watchOS 9.0, *).On iOS 16, calling these accessors can crash inside Foundation's URL parsing. The trap surfaces at
URL.host(percentEncoded:)even though.host()is never called from this code path — the new percent-encoded accessors appear to share internal component-parsing code with host parsing on that OS version. Swift Forums has a report of the same crash signature triggered by a different percent-encoded accessor (URL.query(percentEncoded:)), also surfacing insideURL.host(percentEncoded:): https://forums.swift.org/t/does-url-query-percentencoded-calls-url-host-percentencoded-under-the-hood/70452Since
HTTPClient.TracingConfiguration.init()defaults toInstrumentationSystem.tracer(typically a no-op tracer when the app hasn't bootstrapped one), this code path runs on effectively every request made throughHTTPClient/HTTP2ClientRequestHandler, not only when an app has opted into tracing. That makes this a crash-on-every-request risk for any app running on affected iOS 16 devices.Fix
Raise the
#availablegate from iOS 16/macOS 13 to iOS 17/macOS 14 (and the corresponding tvOS/watchOS versions), so iOS 16 falls back to the existing legacy branch using the older, non-percent-encodeduser/passwordproperties, which do not hit this bug.Testing
swift buildsucceeds.nio.transportservices.eventloop.taskqueue, with the trap inURL.host(percentEncoded:)reached viastringWithUserAndPasswordStripped.getter→handleRequestTracingAttributes→RequestBag.LoopBoundState.startRequestSpan(tracer:)→RequestBag.willExecuteRequest0(_:)→HTTP2ClientRequestHandler.write(context:data:promise:).